5.3

CVSS3.1

CVE-2025-10731 - ReviewX โ€“ WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema โ€ฆ

The ReviewX โ€“ WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.12 via the allReminderSettings function. This makes it possible for unauthentiโ€ฆ

๐Ÿ“… Published: March 23, 2026, 5:29 a.m. ๐Ÿ”„ Last Modified: April 24, 2026, 4:32 p.m.

5.3

CVSS4.0

CVE-2026-4574 - SourceCodester Simple E-learning System User Profile Update sql injection

A vulnerability was detected in SourceCodester Simple E-learning System 1.0. This vulnerability affects unknown code of the component User Profile Update Handler. The manipulation of the argument firstName results in sql injection. It is possible to launch the attack remotely. The exploit is now puโ€ฆ

๐Ÿ“… Published: March 23, 2026, 5:01 a.m. ๐Ÿ”„ Last Modified: April 24, 2026, 4:32 p.m.

5.3

CVSS4.0

CVE-2026-4573 - SourceCodester Simple E-learning System HTTP GET Parameter delete_post.php sql injection

A security vulnerability has been detected in SourceCodester Simple E-learning System 1.0. This affects an unknown part of the file /includes/form_handlers/delete_post.php of the component HTTP GET Parameter Handler. The manipulation of the argument post_id leads to sql injection. It is possible toโ€ฆ

๐Ÿ“… Published: March 23, 2026, 5:01 a.m. ๐Ÿ”„ Last Modified: April 24, 2026, 4:32 p.m.

5.1

CVSS4.0

CVE-2026-4603 - jsrsasign: jsrsasign: Cryptographic operations impacted by division by zero via malicious JSON Web โ€ฆ

Versions of the package jsrsasign before 11.1.1 are vulnerable to Division by zero due to the RSASetPublic/KEYUTIL parsing path in ext/rsa.js and the BigInteger.modPowInt reduction logic in ext/jsbn.js. An attacker can force RSA public-key operations (e.g., verify and encryption) to collapse to detโ€ฆ

๐Ÿ“… Published: March 23, 2026, 5 a.m. ๐Ÿ”„ Last Modified: March 25, 2026, 2:49 p.m.

9.4

CVSS4.0

CVE-2026-4601 - jsrsasign: jsrsasign: Private Key Recovery via Missing Cryptographic Step in DSA Signing

Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invalid signature withoutโ€ฆ

๐Ÿ“… Published: March 23, 2026, 5 a.m. ๐Ÿ”„ Last Modified: March 25, 2026, 2:49 p.m.

9.3

CVSS4.0

CVE-2026-4599 - jsrsasign: jsrsasign: Private key recovery via incomplete comparison checks biasing DSA nonces

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect comparโ€ฆ

๐Ÿ“… Published: March 23, 2026, 5 a.m. ๐Ÿ”„ Last Modified: March 25, 2026, 2:49 p.m.

8.7

CVSS4.0

CVE-2026-4598 - jsrsasign: jsrsasign: Denial of Service via infinite loop in bnModInverse function with crafted inpโ€ฆ

Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives zero or negative inputs, allowing an attacker to hang the process permanently by supplying such crafted values (e.g., โ€ฆ

๐Ÿ“… Published: March 23, 2026, 5 a.m. ๐Ÿ”„ Last Modified: March 25, 2026, 2:49 p.m.

8.7

CVSS4.0

CVE-2026-4602 - jsrsasign: jsrsasign: Signature verification bypass via negative exponent handling

Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js. An attacker can force the computation of incorrect modular inverses and break signature verification by calling modPow with a negative expโ€ฆ

๐Ÿ“… Published: March 23, 2026, 5 a.m. ๐Ÿ”„ Last Modified: March 25, 2026, 2:49 p.m.

9.1

CVSS4.0

CVE-2026-4600 - jsrsasign: jsrsasign: Cryptographic signature forgery via malicious DSA domain parameters

Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in KJUR.crypto.DSA.setPublic (and the related DSA/X509 verification flow in src/dsa-2.0.js). An attacker can forge DSA signatures or X.509 certiโ€ฆ

๐Ÿ“… Published: March 23, 2026, 5 a.m. ๐Ÿ”„ Last Modified: March 25, 2026, 2:49 p.m.

6.5

CVSS3.1

CVE-2025-10736 - ReviewX โ€“ WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema โ€ฆ

The ReviewX โ€“ WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to unauthorized access of data due to improper authorization checks on the userAccessibility() function in all versions up to, and including, 2.2.10. Thisโ€ฆ

๐Ÿ“… Published: March 23, 2026, 4:26 a.m. ๐Ÿ”„ Last Modified: April 24, 2026, 4:32 p.m.
Total resulsts: 349182
Page 976 of 34,919
ยซ previous page ยป next page
Filters